GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
Low
GHSA-v3j6-27vc-7pw2
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
Moderate
GHSA-56m6-8q75-f2rw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
Moderate
CVE-2026-55597
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
High
CVE-2026-57146
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
High
CVE-2026-57142
was published
for
praisonai
(pip)
Jun 18, 2026
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
High
CVE-2026-57133
was published
for
praisonai
(npm)
Jun 18, 2026
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
High
CVE-2026-57137
was published
for
praisonai
(npm)
Jun 18, 2026
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
Critical
CVE-2026-57139
was published
for
praisonai
(npm)
Jun 18, 2026
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
Critical
CVE-2026-57140
was published
for
praisonai
(npm)
Jun 18, 2026
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
High
CVE-2026-57136
was published
for
praisonai
(npm)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API